Your practical guide to accredited IT service management certification, trusted by technology teams, clients, and service-driven organisations worldwide.
Delivering IT services consistently and reliably is harder than it looks. ISO/IEC 20000-1 certification demonstrates that your organisation has a structured, independently audited system for planning, delivering, and improving IT services, giving clients, procurement teams, and stakeholders the confidence that your service management is built on a proven international framework, not just internal good practice.
ISO/IEC 20000-1 is the international standard for IT Service Management Systems (SMS), developed jointly by the International Organization for Standardization and the International Electrotechnical Commission. It defines the requirements for an organisation to establish, implement, maintain, and continually improve a service management system, ensuring IT services are delivered in a planned, controlled, and customer-focused way.
The current version, ISO/IEC 20000-1:2018, was significantly updated to align with the Annex SL framework, bringing it into structural harmony with ISO 9001, ISO 27001, and other major management system standards. This makes it considerably easier to integrate with existing certifications and audit programmes. The 2018 version also introduced a stronger emphasis on service planning, relationship management, and the management of services provided by third parties and customers, reflecting the reality of how modern IT services are actually delivered.
ISO/IEC 20000-1 is closely associated with ITIL, the widely adopted IT service management framework, and organisations already working within ITIL practices will find significant overlap with the standard’s requirements. However, ISO/IEC 20000-1 is an independently certifiable standard, while ITIL is a framework of guidance, and the two serve different but complementary purposes.
The standard applies to any organisation that delivers IT services, whether internally to its own business units or externally to paying customers. This includes managed service providers, IT outsourcing companies, in-house IT departments, cloud service providers, and technology support organisations of every size.
Get in touch with Pacific Certifications today for a seamless, transparent path to accredited registration. Our global experts are available 24/7 to support your operational needs.
ISO/IEC 20000-1:2018 is built on the Annex SL framework and follows the PDCA (Plan-Do-Check-Act) cycle as its core operational methodology, consistent with other major ISO management system standards.

From initial scoping to certified status, our auditors bring real IT service management experience to every stage of your certification journey.
Receive an independently audited, internationally recognised ISO/IEC 20000-1 certificate through a clear, structured two-stage audit process.
Build internal capability across your IT service management and operations teams with training pathways from awareness through to lead auditor level.
Already certified to ISO 27001 or ISO 9001? We can align audit scheduling and reduce duplication where your systems overlap, making the overall programme more efficient.
Review your existing IT service management practices internally against ISO/IEC 20000-1 requirements before the formal audit, so your service processes and documentation are ready when it counts.
ISO/IEC 20000-1 has evolved significantly across its three versions, each reflecting how IT service management expectations have developed in an increasingly complex and interconnected technology environment.
| Parameter | ISO/IEC 20000-1:2005 | ISO/IEC 20000-1:2011 | ISO/IEC 20000-1:2018 |
|---|---|---|---|
| Structural Template | Standalone structure aligned with BS 15000. | Revised structure with improved clarity but still independent of other ISO frameworks. | Annex SL harmonized structure enabling integration with ISO 27001, ISO 9001, and other standards. |
| Scope of Services | Focused primarily on internally delivered IT services. | Broader applicability to managed service providers and outsourced IT delivery. | Explicit requirements for managing services delivered by third parties, partners, and customers. |
| Risk Approach | Limited risk consideration within service processes. | Some risk-based thinking introduced across service planning. | Risk-based thinking fully embedded across the SMS, consistent with other Annex SL standards. |
| Leadership | Management commitment required but loosely defined. | Clearer management responsibility requirements. | Direct top management accountability with explicit leadership obligations throughout. |
| Documentation | Prescriptive documentation requirements. | Slightly more flexible documentation approach. | Flexible, outcome-focused documentation aligned with organisational context. |
| Focus Area | Process compliance and ITIL alignment. | Service quality and customer-focused delivery. | Continual improvement, third-party service management, and integration with broader governance frameworks. |
ISO/IEC 20000-1 is underpinned by a set of service management principles that prioritise structured, customer-focused, and continuously improving IT service delivery.
IT services must be managed within a documented, structured system that defines how services are planned, delivered, monitored, and improved, not managed informally or reactively.
Service requirements must be clearly understood, agreed, and met. Customer satisfaction and the effective management of service relationships are central to the standard.
Top management must actively drive the SMS, allocate resources, and take visible accountability for service management performance at an organisational level.
Effective IT service delivery depends on defined, interconnected processes covering the full service lifecycle, from design and transition through to delivery, support, and improvement.
Risks and opportunities affecting service delivery must be identified, assessed, and addressed systematically, including risks associated with third-party and customer-supplied services.
Where services involve external suppliers, partners, or customer contributions, those relationships must be formally managed with clear agreements, monitoring, and accountability.
The SMS must drive ongoing improvement in both service performance and the management system itself, using data, audits, and customer feedback as the basis for action.
ISO/IEC 20000-1:2018 follows the Annex SL 10-clause framework, with Clauses 4 through 10 defining the formal requirements assessed during certification.
| Clause | Title | Scope & Requirement Objective |
|---|---|---|
| Clause 4 | Context of the Organisation | Identify internal and external factors affecting energy performance, understand stakeholder needs, and define the scope of your EnMS. |
| Clause 5 | Leadership | Top management must demonstrate commitment, establish an energy policy, and assign clear roles and responsibilities. |
| Clause 6 | Planning | Conduct an energy review, establish a baseline, identify significant energy uses, and set measurable objectives and targets. |
| Clause 7 | Support | Ensure adequate resources, competence, awareness, communication, and control of documented information. |
| Clause 8 | Operation | Plan and control operations and processes related to significant energy uses, including design and procurement decisions. |
| Clause 9 | Performance Evaluation | Monitor and measure energy performance against the baseline, conduct internal audits, and carry out management reviews. |
| Clause 10 | Improvement | Address non-conformities, implement corrective actions, and drive continual improvement in energy performance and the EnMS. |
ISO/IEC 20000-1 places particular emphasis on Clause 8, which covers the operational service management processes that define how IT services are actually planned, delivered, and supported. These include:
| Process Group | Key Processes |
|---|---|
| Service Portfolio | Service catalogue management, service level management. |
| Relationship and Agreement | Business relationship management, supplier management, service level agreement management. |
| Supply | Budget and accounting, capacity and demand, availability, service continuity, information security. |
| Resolution | Incident management, service request management, problem management. |
| Control | Configuration management, change management, release and deployment management. |
Everything you need to prepare for ISO/IEC 20000-1 certification, in one place.
The path to certification balances system building with rigorous auditing.
Submit your application and tell us about your organisation, the scope of IT services covered, and any existing management system certifications.
Before the formal audit begins, review your existing IT service management processes internally against ISO/IEC 20000-1 requirements to identify and address any gaps.
A documentation review to confirm your SMS, service management processes, and supporting documentation are adequately developed and ready for the main assessment.
Our auditor evaluates whether your SMS is fully implemented and effective across all in-scope service management processes, including incident, change, and supplier management.
Upon successful completion, your ISO/IEC 20000-1 certificate is issued, valid for three years.
Annual surveillance audits maintain your certification, followed by full recertification at the end of the three-year cycle.
For a standard organisation, the certification process typically follows a ten-week timeline.
| Week | Activity | Core Milestones & Focus Areas |
|---|---|---|
| Week 1 | Application & Scoping | Submit your application and define the scope of your SMS and the IT services included. |
| Week 2 | Gap Analysis | Internally review existing service management processes and documentation against ISO/IEC 20000-1 requirements. |
| Weeks 3-4 | SMS Implementation | Deploy or refine service management processes, establish service level agreements, and ensure documented information is in place. |
| Weeks 5-6 | Stage 1 Audit | Our auditor reviews your SMS documentation and service process documentation to confirm readiness for the main assessment. |
| Weeks 7-8 | Stage 2 Audit | Full on-site or remote evaluation of your SMS implementation across all in-scope service management processes. |
| Week 9 | Technical Review | Address any findings, close non-conformities, and finalise the certification review. |
| Week 10 | Certificate Issuance | Receive your accredited ISO/IEC 20000-1 certificate upon successful completion of the assessment. |
Note: The timeline is indicative and may vary depending on the number of services in scope, organisational complexity, existing process maturity, and completion of any corrective actions required.
ISO/IEC 20000-1 certification costs vary depending on the scope of IT services covered, the size of your organisation, the number of locations involved, and the maturity of your existing service management processes. Organisations integrating ISO/IEC 20000-1 with ISO 27001 or ISO 9001 under a combined audit programme will generally find it more efficient and cost-effective than a standalone assessment.
At Pacific Certifications, we offer transparent, competitive pricing with no hidden charges. Contact us for a tailored quote or use our free cost calculator to get an instant estimate.
IT services sit at the heart of nearly every organisation, and the expectations placed on service providers have never been higher. As enterprise clients and government procurement bodies are demanding verified evidence that their IT service partners operate within a structured, audited management framework, not just a well-intentioned team with good intentions and an ITIL textbook.
Managed service providers, outsourcing companies, and in-house IT functions that cannot demonstrate ISO/IEC 20000-1 certification are increasingly finding themselves excluded from procurement shortlists before conversations even begin. Certification signals operational maturity, accountability, and a commitment to service quality that clients can rely on and verify independently.
We provide deep, sector-specific auditing aligned directly with your daily operations.
Build the internal expertise your organisation needs to implement, maintain, and audit an ISO/IEC 20000-1 compliant service management system.
For professionals looking to conduct and lead ISO/IEC 20000-1 audits with confidence and internationally recognised credentials.
For those responsible for designing, implementing, and maintaining an IT Service Management System within their organisation.
For IT teams and service management professionals who need a clear, practical understanding of ISO/IEC 20000-1 and what it means for how services are planned, delivered, and improved.
We are not just a certification body, we are the partner that helps your organisation earn trust, improve performance, and grow with confidence.
Accredited by the ABIS (Accreditation Board for International Standards), our certificates are accepted by clients, regulators, and procurement bodies worldwide.
Our auditors bring sector-specific knowledge to every engagement, ensuring your audit is relevant, thorough, and conducted by someone who understands your business.
We operate globally with the capability to conduct both remote and on-site audits, delivering consistent, high-quality certification services wherever you are.
From your first enquiry to your final certificate, we keep things clear, efficient, and tailored to your organisation — no unnecessary delays, no hidden costs.
ISO/IEC 20000-1 certification is independent confirmation that your organisation delivers IT services within a structured, audited management system that meets internationally recognised requirements. For managed service providers and IT teams, it is increasingly the standard clients and procurement bodies look for when assessing whether a service partner can be trusted to deliver reliably and consistently.
ITIL is a framework of best practice guidance for IT service management. ISO/IEC 20000-1 is a certifiable standard that defines what a service management system must achieve. The two are complementary, and organisations already working within ITIL practices will find significant alignment with the standard's requirements, but ITIL adoption alone does not lead to ISO/IEC 20000-1 certification.
Most organisations complete the certification process within 3 to 6 months, depending on the scope of services covered, the maturity of existing processes, and the complexity of the organisation. Our team will provide a realistic timeline from your first conversation with us.
Costs depend on the scope of IT services covered, organisation size, number of locations, and process maturity. Pacific Certifications offers transparent, competitive pricing with no hidden charges. Contact us or use our cost calculator for a tailored estimate.
Certification is voluntary, but it is increasingly a practical requirement in government and enterprise procurement processes for managed service and outsourcing contracts. In the IT services sector, it has moved from being a differentiator to an expected baseline for serious service providers.
Certificates are valid for three years, with annual surveillance audits conducted throughout that period to confirm your SMS remains effective and that service performance continues to meet requirements. A full recertification audit takes place at the end of the three-year cycle.
Yes. Many elements of the SMS audit, including process documentation, service records, and management reviews, can be assessed remotely. Where on-site assessment adds value, particularly for organisations with physical infrastructure or complex multi-location service delivery, our auditors are available to conduct on-site assessments as well.
Yes. ISO/IEC 20000-1:2018 shares the Annex SL common framework with ISO 27001 and ISO 9001, making integration of audits and management systems straightforward. Many IT service organisations hold all three certifications and audit them together in a single, efficient programme.
The scope defines which IT services, locations, and organisational units are covered by the certification. Defining the right scope is an important early step, as it determines what is assessed during the audit and what your certificate covers. Our team will help you think through the right scope from the outset.
If non-conformities are identified during the audit, you will be given a defined timeframe to investigate, correct, and provide evidence of resolution. Our auditors approach every engagement constructively, with the aim of helping your organisation achieve certification, not creating unnecessary obstacles to getting there.
Get in touch with us today. Complete the form and we’ll be happy to assist you.
This will close in 20 seconds
WhatsApp us